NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

SuBDivisions23's avatar
Aug 07, 2025
Solved

Bridge 2 Networks with SRX5308 Help

Hello, Here is what I am trying to accomplish.

 

Building A - 192.168.0.x

Building B - 192.168.1.x

 

I have a ubiquiti wifi antenna that is connecting both buildings for the SOLE purpose of building B, accessing building A's NAS Drive, 192.168.0.10

 

I have been told a bunch of how to scenarios, but i cant get it working right as in segmenting each network separate so both DHCP servers do not conflict.  I want both networks to remain independant, only a handful of PC's at building B to access the Nas Drive at building A.

 

(A VPN was not able to accomplish this fast enough, even with Gigabit Internet, SMD doesn't like VPN's).

 

So i was told on the srx5308 to plug one of the antenna's into one of the Quad WAN Ports, lets say Wan2..  Give it a /29 IP Address.  Then do the same on the other building (which has a non-netgear firewall).. but for now lets concentrate on the setup in building B with the Srx5308.

 

This is what i was told:

 

  • On the SRX5308 plug the bridge into one of the spare WAN ports and assign a small subnet (e.g. 172.16.10.1/29). Page 127 of the manual tells you how to setup static routes.

Problem is, the srx5308 won't let me do this unless i put in a gateway and dns servers on the Wan2 port as far as i can tell.  Also do i turn on DHCP on that /29 range or leave it solo and static the IPs in it..

 

Fwiw, i had this working buy just plugging everything in and using IP ALias's on the windows machines, but the dhcp servers on both ends could obviously not coexist..  I need to keep the network separate but have this one tunnel to get to that nas drive thru the antenna connection (the buildings are approx 900 ft away, the antennas work very very well).

 

Appreciate any assistance.

  • I got it working.  Thanks to c3po2​ for the guided assistance..   In a nutshell here is what i did.  My brain was cramping for days with this.

     

    The First Key, was properly setting up the VLAN's on Both Firewalls.  In the SRX5308, I created VLAN20 with the IP 172.16.10.1/29 located in Building A.  Building B TPLink ER605 I created VLAN20 with the IP 172.16.10.2/29.  The SRX5308 VLAN, has Inter-Vlan Routing box enabled. *Note - The Ubiquiti Nano 5ac Antenna is plugged into LAN 3 on the SRX5308.. NOT the Wan port.  Shown below are the settings for the VLAN (called CBBridge).   As you can see also, i only have Port 3 checked off, where the Antenna is plugged into.

    Next the Routing on the SRX5308 shown Below.  The cavieat that i didn't figure out til i tried it, was the Gateway.  I kept thinking the 172.16.10.1 IP of the Vlan on the SEX5308 was the one to use, i was incorrect.  I had to use the 172.16.10.2 gateway, which is the IP of the VLAN on the TP Router in Building 2.  Before i figured that out, i was able to ping things using the internal diagnostics of both firewalls, but unable to get the Lan to ping (which the routes fixed).. Here is that config.

    This is the routing i setup, which is a single static route for the people at building A to get to building B's Nas drive.

     

    On Building B's side,  this is the setup. (TPLink ER605)

     

     

    This is the static route i created on the TP Link so the Building A network can communicate to the Building B LAN thru what i called "UbiquitiBridge" VLAN.

     

    As you can see, its routing all the 192.168.1.1 traffic thru 172.16.10.1 which is the gateway of the VLAN on the SRX5308 in Building A.

     

    Now, all the machines that have mapped drives to the NAS Share at Building B are operating at full gigabit speed, and I am extremely happy.

     

    Thanks to everyone for the help, and guidance.  I hope this can help others who need to do the same thing.

     

    *Note - while i haven't yet gone on site to make sure both DHCP servers are not in any way messing with anything, i created a ALWAYS BLOCK rule on the SRX5308 to Block UDP port 67 from the IP range of the VLAN.*

24 Replies

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More